Two different 28-day rules
"The 28-day TPS rule" gets used to mean two different things, and the difference matters. The first rule is about your data: TPS screening data should be no more than 28 days old when you rely on it. The second is about the register itself: a TPS registration becomes legally enforceable 28 days after the number joins. One is an obligation on you; the other is a grace period that protects you. Most teams have heard of one and not the other.
Rule one: screening data no older than 28 days
When you screen a list against TPS, you are checking it against a copy of the register, and that copy starts ageing the moment it is cut. The industry standard, set by the Data & Marketing Association which operates TPS, is that screening data must be refreshed at least every 28 days. DMA-licensed list cleaners are required to work to that cadence as a condition of the licence, and TPSClear holds itself to the same ceiling: the reference data behind every check is never older than 28 days, with daily refresh in practice.
The consequence for you: a "screened" flag on a contact has a shelf life. If your last batch ran in January and you are dialling in March, you are relying on data that the rule itself says is stale. Screening is not an event, it is a cadence.
Where the 28 days comes from
Not from the law. PECR never mentions 28 days, or any schedule at all; regulation 21 simply prohibits unsolicited marketing calls to registered numbers. The 28-day figure is the industry's operational answer to the question "how fresh is fresh enough to be reasonable?", and it earns its authority from two places: the DMA bakes it into TPS licensing, and the ICO's direct marketing guidance expects screening close enough to the call that the data is current. Screen on a 28-day cycle and you can show a complaint investigator that your records were never more than four weeks stale. That is a defensible position. It is not, as I argue below, the best available one.
Rule two: a registration is enforceable after 28 days
The other 28 days runs in your favour. When a subscriber registers a number with TPS or CTPS, the registration becomes legally enforceable 28 days later. A number added to the register last Tuesday is not yet actionable if you call it today. This exists precisely because screening is periodic: it gives callers working on a compliant 28-day cycle time for the new registration to reach their data.
I would not build anything on that gap. It is a backstop for honest cadence, not callable inventory, and a complaint from someone who registered three weeks ago still costs you handling time even when it cannot become a penalty.
What 28 days of drift actually costs
TPS is not static. People register every day, and roughly 28 million consumer numbers already sit on the register alongside 3 million corporate ones on CTPS. Between any two screening runs, some of your contacts will join. On a list of 10,000 UK contacts, even a fraction of a percent registering per month means a steady trickle of numbers that were clean at your last check and are registered by the time a rep dials. A 28-day cycle catches each of those up to 28 days late; a quarterly cycle, up to 89 days late.
That drift is exactly the gap between "we screen" and "we were compliant on the call the complaint is about". Since February 2026 the ICO's penalty ceiling for PECR breaches is £17.5 million or 4% of global turnover, which changes the arithmetic on how much drift is worth tolerating.
Is 28 days enough for the ICO?
Usually, yes, as a floor. The ICO's test is reasonableness for your volume and risk, and the public enforcement record shows penalties for not screening at all, not for screening monthly instead of weekly. But the closer you screen to dial-time, the less there is to argue about. Real-time screening on every phone-number change, which is what TPSClear does inside HubSpot, shrinks the drift window from four weeks to minutes and makes the 28-day debate mostly academic. I have set out who needs which cadence, by team size and call volume, in how often should you check TPS.
One development worth watching: the DMA is reportedly weighing a usage-based royalty on TPS checks, which would make cadence a line-item cost for the first time. If it lands, the wrong response is cutting screening frequency to save pennies; I have run the numbers in the proposed TPS royalty fee.
One-line conclusion
The 28-day rule is two rules: keep your screening data no more than 28 days old (the DMA licence standard, and your floor), and remember a fresh registration only becomes enforceable after 28 days (a backstop, not an invitation); treat 28 days as the minimum cadence and dial-time screening as the target.